Executive brief
Oracle GlassFish Server, a platform used for developing and deploying Java applications, contains a security vulnerability in its core component. An attacker could use specially crafted email communications to trick a user into interacting with the system, leading to unauthorized changes to the server's data. This could result in the corruption or unauthorized modification of business information managed by the server.
Technical details
A vulnerability in the Core subcomponent of Oracle GlassFish Server allows an unauthenticated, remote attacker to compromise the system via the SMTP protocol. The flaw is classified as 'easily exploitable' but requires user interaction (UI:R) to succeed. Successful exploitation enables an attacker to perform unauthorized updates, insertions, or deletions of data accessible to the GlassFish Server. The vulnerability affects versions 2.1.1, 3.0.1, and 3.1.2. Oracle addressed this issue in the January 2017 Critical Patch Update.
Affected products
- Oracle GlassFish Server 2.1.1, 3.0.1, 3.1.2
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle January 2017 Critical Patch Update published